Citrix cybersecurity
– urzine/Getty Images

Cisco is under pressure from the U.S. government over critical firewall flaws that may have allowed for a nation-state backed breach.

In a letter to Cisco CEO Chuck Robbins last week, U.S. Senator Bill Cassidy referenced an Emergency Directive issued by the Cybersecurity and Infrastructure Security Agency (CISA) in September in response to zero-day exploits targeting Cisco's Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) devices.

The exploits posed an "unacceptable risk" to federal information systems, allowing for remote code execution and privilege escalation.

Federal agencies were given 24 hours to account for all ASA and Firepower devices, collect forensics and identify any compromises, as well as upgrade devices and disconnect those at end of support.

The U.K.'s National Cyber Security Centre issued a similar proclamation, with both bodies linking the attack to the ArcaneDoor campaign, which Cisco reported in early 2024.

In his letter, Cassidy claimed at least one federal agency had reportedly been breached as a result of the vulnerability, something yet to be corroborated by Cisco.

The senator requested answers on whether Cisco had identified any specific threats to individual customers, alongside details of its communication plan with customers, including federal agencies, such as the departments of Health, Education, and Labor, which Cassidy oversees as committee chair.

Cisco was given until October 27 to respond to Cassidy's queries.

Nation-state threats

The senator’s message to Cisco also called out the growing cyber threat from “hostile actors”, including China, Russia, and Iran. A Censys report from May last year potentially pinned the ArcaneDoor campaign on a China-based actor, with connections “to multiple major Chinese networks and the presence of Chinese-developed anti-censorship software.”

The attacks take advantage of a remote code execution vulnerability (CVE-2025-20333) and a privilege escalation flaw (CVE-2025-20362). Statistics from the Shadowserver Foundation estimated that almost 50,000 Cisco firewall devices are at risk from the vulnerabilities.

Further compounding a bad week in cybersecurity, security firm F5 revealed it was the victim of a China-linked attack.

In a filing with the Securities and Exchange Commission (SEC), F5 reported a threat actor had breached its networks and gained “long-term, persistent access” to certain areas of its system, giving access to parts of the company’s BIG-IP source code and information about undisclosed vulnerabilities that it had been working on.

Bloomberg reported sources claiming the hackers had access to F5’s network for at least a year.

Earlier this year, a historical Cisco bug was revealed as being exploited by a Russian espionage group, leading to an urgent briefing from the FBI.

The exploit concerned Cisco’s Simple Network Management Protocol (SNMP) on retired networking devices running an unpatched exploit.